HCL Volt MX Cloud status
Current status and incident report
Foundry V9 SP5 FP2 HF2 Release
Maintenance window: Friday, April 07, 2023 00:01 to 04:00Enterprise App Store
An issue related to password reset has been fixed.
Impact Level : minor
Minor downtime is possible for the impacted Cloud services while this maintenance is being performed. The scheduled maintenance is designed to mitigate disruptions to service availability and performance for the impacted Cloud services. However, it is possible for the impacted Cloud services to be unavailable and/or performance degraded for a short period of time during the maintenance window. Note that no changes are being applied for other Cloud services outside of the list of impacted services above and no service availability or performance disruption is expected for other Cloud services.
Foundry V9 SP5 FP2 Release
Maintenance window: Monday, March 20, 2023 00:01 to 04:00Cloud Management Console
Fixed support for OpenAPI 3.0 specific annotations and features such as circular dependencies for Swagger-based adapters.
Impact Level : minor
Minor downtime is possible for the impacted Cloud services while this maintenance is being performed. The scheduled maintenance is designed to mitigate disruptions to service availability and performance for the impacted Cloud services. However, it is possible for the impacted Cloud services to be unavailable and/or performance degraded for a short period of time during the maintenance window. Note that no changes are being applied for other Cloud services outside of the list of impacted services above and no service availability or performance disruption is expected for other Cloud services.
Foundry V9 SP5 FP0 HF1 Release
Maintenance window: Thursday, March 9, 2023 00:01 to 04:00Foundry Identity
Fixed the issue LinkedIn Identity service not working when PKCE is disabled.
Engagement
Fixed cross-site scripting vulnerability in Engagement access management page.
Impact Level : minor
Minor downtime is possible for the impacted Cloud services while this maintenance is being performed. The scheduled maintenance is designed to mitigate disruptions to service availability and performance for the impacted Cloud services. However, it is possible for the impacted Cloud services to be unavailable and/or performance degraded for a short period of time during the maintenance window. Note that no changes are being applied for other Cloud services outside of the list of impacted services above and no service availability or performance disruption is expected for other Cloud services.
Foundry V9 SP5 (Curie) Release
Maintenance window: Monday, December 5, 2022 00:01 to 04:00Foundry Integration Server
New Volt MX Microservices connector for simplified Developer experience
Enhanced functionality for Microapps
Support for authentication into Foundry Console using AD SAML
Improved Service Monitoring
Advanced Workflow capabilities with Parallel paths
Added Looping support for workflows
Improved security for caching using Redis
Added support for WebSockets to the Volt MX Foundry Cloud
Added support to reconfigure the scheme for Swagger 2.0 services
Added the Foundry Workflow Adapter in Integration Services
Enhancements to Workflow Audit history
Middleware Integration with Volt MX Metering Service Client Library
Updates to Server Events APIs
Cloud Management Console
Developer Portal Members will now be able to see the list of other registered users
Enable additional Server Side Validations for Email Hyperlink Injection attacks
Added Content Security Policy in response header to protect against clickjacking attacks
Fixed Unable to load WSDL file error for SOAP Services
Enhanced extensibility for Integration and Object Services
Implemented calling stored procedures by ordinal position of parameters
Added support for Oracle CLOB and NCLOB data types
Fixed a timestamp parsing issue in stored procedures and functions
Composite app publish status refresh issues fixed
Publish time out increased from default 20 seconds to 60 seconds to allow bigger customer apps to be publishable
Supporting Modularity of Foundry Apps
Added OpenAPI Specification support for Object Verb Mapping
Added support for Custom Front-End URLs in Object Services
Added the Integration Service trigger type to Workflow services
Added support to view linked Java Pre and Post Processors for a Foundry App
Added a Version Upgrade mechanism to MFCLI
Updates to Engagement Adapter
For some customers, snapshot creation of extended services failed during Publish. This has been fixed
Fixed SAML provider configuration validation issue
Fixed issue where headers could not be added or saved for locked services
Fixed issue where custom operations could not be deleted for locked operations
Foundry Identity
Improved security against clickjacking attacks.
jQuery upgrade from 3.5.0 to 3.6.0
Improved support for OAuth connections using private key JWT
Added support to use PKCE in JavaScript SDK
Added support to replace Identity Service references
Fixed issue where Custom identity provider’s Claims token obtained in refresh flow was not working for Foundry integration services
Engagement
Improved support for Events notifications
Enhancements to Email API to send emails without audience member creation
Support the engagement application creation without the certificate configuration
Enhancements to the engagement adapter to support API key
Deprecated support for Blackberry
AppFactory
Cucumber Support for Foundry Testing in AppFactory
Foundry Build Process from AppFactory Command Line
IOS & Android Cross App Testing support
Target Test Data from environments
Support for Istanbul testing code coverage for Volt MX built apps using the Volt MX Testing Framework. Ensure every line of your code is tested, every time you test
Group failed tests together and re-run those test as part of AppFactory’s testing process with the Volt MX Testing Framework
Web based cross app testing backported to 9.2 to allow testers to instrument test scenarios that take the test case outside the Volt MX Testing Framework, like OAuth
Micro app test case support for combining base micro app test cases to a larger test case within a composite app
Command Line support for create new AppFactory projects and building Iris based apps within AppFactory from the command line
Apple API key support for signing iOS based apps
Regenerate Foundry object models for Iris based apps every time you build with AppFactory
Added support for Microservices
Added support for Cross Application Testing
Added OAuth support for testing deployed web apps
Impact Level : minor
Minor downtime is possible for the impacted Cloud services while this maintenance is being performed. The scheduled maintenance is designed to mitigate disruptions to service availability and performance for the impacted Cloud services. However, it is possible for the impacted Cloud services to be unavailable and/or performance degraded for a short period of time during the maintenance window. Note that no changes are being applied for other Cloud services outside of the list of impacted services above and no service availability or performance disruption is expected for other Cloud services.
Cloud SSL Certificate Updates
Maintenance window: July 16, 2022 00:01 to 04:00 UTC Impacted Cloud services:Cloud SSL certificates will be updated for the following services
App services (*.hclvoltmx.net)
Dedicatated Identity services (*.auth.hclvoltmx.net)
⚠️ If your application uses public key pinning application updates should be made but are not necessary at this time. Customers that are using public key pinning should include the additional certificate pins in the JSON below.
⚠️ For customers using full SSL certificate pinning, please open a support ticket requesting a copy of the updated HCL certificates.
⚠️ If you are using full SSL certificate pinning, your applications must be published before the this HCL SSL certificate update on the cloud servers or the applications may no longer be able to connect to HCL servers.
If necessary, you can submit your applications for expedited approval (e.g., Apple has an expedited approval process for critical bugs, or in this case, pinned certificates).
Impact Level : high
Customer applications that have pinned the full SSL certificate must be updated as described above prior to this maintenance window. Customer applications that have not pinned SSL certificates will not be affected and will experience no service disruptions during this maintenance window.
Customers using public key pinning should include the updates to the pins listed below in the next publish of your mobile applications to the relevant app store. This set of pins also include the pins for additional backup SSL keys. HCL will be rotating certificates again later this year.
When mobile applications add the additional security of pinning a certificate for VoltMX servers, the application is built with information that allows it to use only locked down certificates. Verification of the SSL certificate, in combination with building the mobile application in protected mode, provides the best security for your mobile application.
The json below contains the necessary pins for Public Key Pinning of the HCL VoltMX Cloud production SSL certificates.
{
"*.hclvoltmx.net" : [
"yjg/9eaEB+Lh68+DeUvX0cOb/+OMDqs3d15snWwRzYs=",
"nV05xy/8ejyoGXvFV/tL+8JavIZ6O7rfU5Z/3RO2N4s=",
"RVIUssObuqwIn/jA6zSNWqdU++8wxHfpm2uJrIJWrOM=",
"q/xZuNZkwiNZ72g+gp7WuEvWMed1T0qTUcr47YpoMWM=",
"NKvrJodATL1podc1DZ0Drd9lzf7SWEmK8oPL7l2g76g="
],
"*.auth.hclvoltmx.net" : [
"CAMXj/DsquaCqbXLe7vpoH18P5ThihnLTVi0wJAr7FE=",
"yjg/9eaEB+Lh68+DeUvX0cOb/+OMDqs3d15snWwRzYs=",
"nV05xy/8ejyoGXvFV/tL+8JavIZ6O7rfU5Z/3RO2N4s=",
"RVIUssObuqwIn/jA6zSNWqdU++8wxHfpm2uJrIJWrOM=",
"q/xZuNZkwiNZ72g+gp7WuEvWMed1T0qTUcr47YpoMWM=",
"NKvrJodATL1podc1DZ0Drd9lzf7SWEmK8oPL7l2g76g="
],
"*.messaging.hclvoltmx.net": [
"RD7OME7ESYWLNadwtTvCqO+DruprSlRPgi0nmrsXPjI=",
"yjg/9eaEB+Lh68+DeUvX0cOb/+OMDqs3d15snWwRzYs=",
"nV05xy/8ejyoGXvFV/tL+8JavIZ6O7rfU5Z/3RO2N4s=",
"RVIUssObuqwIn/jA6zSNWqdU++8wxHfpm2uJrIJWrOM=",
"q/xZuNZkwiNZ72g+gp7WuEvWMed1T0qTUcr47YpoMWM=",
"NKvrJodATL1podc1DZ0Drd9lzf7SWEmK8oPL7l2g76g="
],
"Amazon" : "JSMzqOOrtyOT1kmau6zKhgT676hGgczD5VMdRMyJZFA=",
"Amazon Root CA 1" : "++MBgDH5WGvL9Bcn5Be30cRcL0f5O+NyoXuWtQdX1aI=",
"Go Daddy Secure Certificate Authority - G2": "8Rw90Ej3Ttt8RRkrg+WYDS9n7IS03bk5bjP/UXPtaY8=",
"Go Daddy Root Certificate Authority - G2" : "Ko8tivDrEjiY90yGasP6ZpBU4jwXvHqVvQI0GS3GNdA=",
"Starfield Services Root Certificate Authority - G2" : "KwccWaCgrnaw6tsrrSO61FgLacNgG2MMLq8GE6+oP5I="
}
References
No downtime is expected for the impacted Cloud services while this maintenance is being performed. The scheduled maintenance is designed to mitigate disruptions to service availability and performance for the impacted Cloud services. However, it is possible for the impacted Cloud services to be unavailable and/or performance degraded for a short period of time during the maintenance window. Note that no changes are being applied for other Cloud services outside of the list of impacted services above and no service availability or performance disruption is expected for other Cloud services.
Foundry V9 SP2 FP1 HF9
Maintenance window: June 15, 2022 00:01 to 04:00Foundry Integration Services
Upgrade log4j2 to 2.17.1 to resolve Log4j2 vulnerabilities CVE-2021-45105 and CVE-2021-44832 Upgrade Spring to 5.3.18 to resolve Spring4Shell vulnerability CVE-2022-22965 Upgrade Hibernate to 5.4.33 to resolve Hibernate vulnerability CVE-2020-25638
Impact Level : minor
The full release notes for this update are available on the HCL VoltMX Documentation site.
Minor downtime is possible for the impacted Cloud services while this maintenance is being performed. The scheduled maintenance is designed to mitigate disruptions to service availability and performance for the impacted Cloud services. However, it is possible for the impacted Cloud services to be unavailable and/or performance degraded for a short period of time during the maintenance window. Note that no changes are being applied for other Cloud services outside of the list of impacted services above and no service availability or performance disruption is expected for other Cloud services.
Foundry V9 SP2 FP1 HF8
Maintenance window: May 3, 2022 00:01 to 04:00Foundry Integration Services
Iris Application fails during an upgrade JavaScript Kony API icompatibility updates
Impact Level : minor
The full release notes for this update are available on the HCL VoltMX Documentation site.
Minor downtime is possible for the impacted Cloud services while this maintenance is being performed. The scheduled maintenance is designed to mitigate disruptions to service availability and performance for the impacted Cloud services. However, it is possible for the impacted Cloud services to be unavailable and/or performance degraded for a short period of time during the maintenance window. Note that no changes are being applied for other Cloud services outside of the list of impacted services above and no service availability or performance disruption is expected for other Cloud services.
Foundry V9 SP2 FP1 HF7
Maintenance window: December 17, 2021 00:01 to 04:00Foundry Integration Services
log4j updated to version 2.16 to combat Apache Log4j 2 Vulnerabilites CVE-2021-44228 and CVE-2021-45046
Impact Level : minor
The full release notes for this update are available on the HCL VoltMX Documentation site.
Minor downtime is possible for the impacted Cloud services while this maintenance is being performed. The scheduled maintenance is designed to mitigate disruptions to service availability and performance for the impacted Cloud services. However, it is possible for the impacted Cloud services to be unavailable and/or performance degraded for a short period of time during the maintenance window. Note that no changes are being applied for other Cloud services outside of the list of impacted services above and no service availability or performance disruption is expected for other Cloud services.
CVE-2021-44228 Discovered
Incident window: December 10, 2021There is an additional attack vector reported against the log4j vulnerability and the teams are looking to see if this applies to VoltMX Cloud. This variation claims to work around the JVM protections.
VoltMX Cloud platform and services
CVE-2021-44228 details a flaw that was found in the Java logging library Apache Log4j, in versions 2.0 before 2.15.0, that are also running older JVMs. This allows an attacker to execute code on the server if the system logs an attacker-controlled string value with the attacker’s JNDI LDAP URL and that LDAP server responds with a specially crafted payload.
This is not a critical risk on the VoltMX Platform as more recent JVMs default to not loading code over untrusted URLs. There is no attack vector for LDAP lookups on the VoltMX Platformand as always we would ask customers to be security conscious with all custom java code which they choose to upload to their environment.
The product teams, as part of due diligence, will be incorporating the latest log4j release and VoltMX Cloud will deploy the updates once available.
Impact Level : high
There is no impact to customer’s runtime environment at this time. As always, we would encourage customers to use caution when uploading custom Java code to their environments.
[2021-12-13 11:54 UTC] There is an additional attack vector reported against the log4j vulnerability and the teams are looking to see if this applies to VoltMX Cloud.
[2021-12-13 11:54 UTC] The is a risk from the latest log4j attack vector and we are patching the affected products and will be updating clusters in the coming hours.
[2021-12-14 08:14 UTC] Resolved. All VoltMX environments are fully patched for CVE-2021-44228.